WGU D345 Comprehensive Exam WITH
100 QUESTIONS AND CORRECT ANSWERS
IN OPTION AND RATIONALE UPDATED
2026 GRADED a+
Question 1: What is the primary purpose of an IT audit?
A. To install new software systems
B. To evaluate the effectiveness of IT controls and ensure data integrity
C. To train employees on IT policies
D. To develop new IT infrastructure
Rationale: IT audits are conducted to independently evaluate whether IT controls are properly
designed and operating effectively to protect assets, maintain data integrity, and support
organizational objectives.
Question 2: Which framework is most commonly used for IT governance and management?
A. ITIL
B. COBIT
C. PRINCE2
D. Agile
Rationale: COBIT (Control Objectives for Information and Related Technologies) is the leading
framework developed by ISACA specifically for IT governance and management.
Question 3: What does the acronym SOX stand for?
A. System Operations Exchange
B. Sarbanes-Oxley Act
C. Security Operations Exchange
,D. Standard Operations Xchange
Rationale: The Sarbanes-Oxley Act of 2002 was enacted to protect investors from fraudulent
financial reporting by corporations.
Question 4: Which type of audit evidence is considered the most reliable?
A. Oral testimony
B. Internal documentation
C. Evidence obtained directly by the auditor
D. Photocopies of documents
Rationale: Evidence obtained directly by the auditor through observation, inspection, or
recalculation is considered the most reliable form of audit evidence.
Question 5: What is the CIA triad in information security?
A. Central Intelligence Agency
B. Confidentiality, Integrity, Availability
C. Control, Information, Access
D. Computer, Internet, Access
Rationale: The CIA triad represents the three fundamental principles of information security:
Confidentiality (protection from unauthorized access), Integrity (accuracy of data), and Availability
(accessibility when needed).
Question 6: Which of the following is a preventive control?
A. Audit logs
B. Access control lists
C. Backup procedures
D. Incident response plans
Rationale: Access control lists prevent unauthorized access before it occurs, making them preventive
controls. Audit logs are detective, backups and incident response are corrective.
Question 7: What is the primary role of ISACA?
,A. Developing operating systems
B. Providing certifications and standards for IT audit professionals
C. Manufacturing hardware
D. Creating programming languages
Rationale: ISACA (Information Systems Audit and Control Association) is a professional organization
that develops standards and provides certifications like CISA for IT audit professionals.
Question 8: What does CISA stand for?
A. Computer Information Systems Analyst
B. Certified Information Systems Auditor
C. Central Information Security Administrator
D. Certified Internet Security Auditor
Rationale: CISA is the Certified Information Systems Auditor certification offered by ISACA,
recognized globally for IT audit professionals.
Question 9: What is the first step in the IT audit process?
A. Testing controls
B. Reporting findings
C. Planning the audit
D. Follow-up procedures
Rationale: Planning is the first phase of any audit and includes understanding the business, assessing
risks, and defining the scope of the audit.
Question 10: Which of the following is an example of a detective control?
A. Firewall
B. Intrusion detection system
C. Encryption
D. User training
, Rationale: Intrusion detection systems monitor and identify security breaches after they occur,
making them detective controls.
Question 11: What is materiality in the context of an IT audit?
A. The physical materials used in IT
B. The significance of an amount, transaction, or discrepancy
C. The hardware components
D. The software licenses
Rationale: Materiality refers to the significance of information or errors that could influence
decisions made by users of that information.
Question 12: What is the purpose of segregation of duties?
A. To speed up processes
B. To prevent fraud and errors by dividing responsibilities
C. To reduce costs
D. To improve customer service
Rationale: Segregation of duties is a key internal control that prevents any single individual from
having control over all aspects of a transaction, reducing fraud risk.
Question 13: Which type of testing involves examining the design of controls?
A. Substantive testing
B. Test of controls
C. Compliance testing
D. Analytical testing
Rationale: Tests of controls evaluate whether internal controls are designed appropriately and
operating effectively.
Question 14: What is a walkthrough in an IT audit?
100 QUESTIONS AND CORRECT ANSWERS
IN OPTION AND RATIONALE UPDATED
2026 GRADED a+
Question 1: What is the primary purpose of an IT audit?
A. To install new software systems
B. To evaluate the effectiveness of IT controls and ensure data integrity
C. To train employees on IT policies
D. To develop new IT infrastructure
Rationale: IT audits are conducted to independently evaluate whether IT controls are properly
designed and operating effectively to protect assets, maintain data integrity, and support
organizational objectives.
Question 2: Which framework is most commonly used for IT governance and management?
A. ITIL
B. COBIT
C. PRINCE2
D. Agile
Rationale: COBIT (Control Objectives for Information and Related Technologies) is the leading
framework developed by ISACA specifically for IT governance and management.
Question 3: What does the acronym SOX stand for?
A. System Operations Exchange
B. Sarbanes-Oxley Act
C. Security Operations Exchange
,D. Standard Operations Xchange
Rationale: The Sarbanes-Oxley Act of 2002 was enacted to protect investors from fraudulent
financial reporting by corporations.
Question 4: Which type of audit evidence is considered the most reliable?
A. Oral testimony
B. Internal documentation
C. Evidence obtained directly by the auditor
D. Photocopies of documents
Rationale: Evidence obtained directly by the auditor through observation, inspection, or
recalculation is considered the most reliable form of audit evidence.
Question 5: What is the CIA triad in information security?
A. Central Intelligence Agency
B. Confidentiality, Integrity, Availability
C. Control, Information, Access
D. Computer, Internet, Access
Rationale: The CIA triad represents the three fundamental principles of information security:
Confidentiality (protection from unauthorized access), Integrity (accuracy of data), and Availability
(accessibility when needed).
Question 6: Which of the following is a preventive control?
A. Audit logs
B. Access control lists
C. Backup procedures
D. Incident response plans
Rationale: Access control lists prevent unauthorized access before it occurs, making them preventive
controls. Audit logs are detective, backups and incident response are corrective.
Question 7: What is the primary role of ISACA?
,A. Developing operating systems
B. Providing certifications and standards for IT audit professionals
C. Manufacturing hardware
D. Creating programming languages
Rationale: ISACA (Information Systems Audit and Control Association) is a professional organization
that develops standards and provides certifications like CISA for IT audit professionals.
Question 8: What does CISA stand for?
A. Computer Information Systems Analyst
B. Certified Information Systems Auditor
C. Central Information Security Administrator
D. Certified Internet Security Auditor
Rationale: CISA is the Certified Information Systems Auditor certification offered by ISACA,
recognized globally for IT audit professionals.
Question 9: What is the first step in the IT audit process?
A. Testing controls
B. Reporting findings
C. Planning the audit
D. Follow-up procedures
Rationale: Planning is the first phase of any audit and includes understanding the business, assessing
risks, and defining the scope of the audit.
Question 10: Which of the following is an example of a detective control?
A. Firewall
B. Intrusion detection system
C. Encryption
D. User training
, Rationale: Intrusion detection systems monitor and identify security breaches after they occur,
making them detective controls.
Question 11: What is materiality in the context of an IT audit?
A. The physical materials used in IT
B. The significance of an amount, transaction, or discrepancy
C. The hardware components
D. The software licenses
Rationale: Materiality refers to the significance of information or errors that could influence
decisions made by users of that information.
Question 12: What is the purpose of segregation of duties?
A. To speed up processes
B. To prevent fraud and errors by dividing responsibilities
C. To reduce costs
D. To improve customer service
Rationale: Segregation of duties is a key internal control that prevents any single individual from
having control over all aspects of a transaction, reducing fraud risk.
Question 13: Which type of testing involves examining the design of controls?
A. Substantive testing
B. Test of controls
C. Compliance testing
D. Analytical testing
Rationale: Tests of controls evaluate whether internal controls are designed appropriately and
operating effectively.
Question 14: What is a walkthrough in an IT audit?